librabbitmq-0.9.0-6.el8_10
エラータID: AXSA:2026-1981:01
The librabbitmq packages provide an Advanced Message Queuing Protocol (AMQP) client library that allows you to communicate with AMQP servers using protocol version 0-9-1.
Security Fix(es):
* rabbitmq-c: rabbitmq-c: Heap buffer overflow leading to denial of service (CVE-2026-44236)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-44236
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.
Update packages.
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.
N/A
SRPMS
- librabbitmq-0.9.0-6.el8_10.src.rpm
MD5: 2904916640804ebd81281ade67d89c27
SHA-256: 1f1022e6c2a868f09e1d90d8e85931afaf9dabbd4c863cdb69322c413da1fab6
Size: 157.98 kB
Asianux Server 8 for x86_64
- librabbitmq-0.9.0-6.el8_10.i686.rpm
MD5: f4d464f6de522fcf1dedfe16ff33bcf5
SHA-256: 00c33fba8f963fda13ac090232322763baaf72a7f7147902d8a783360e159910
Size: 50.71 kB - librabbitmq-0.9.0-6.el8_10.x86_64.rpm
MD5: e36378b834c66dfb48b00a2c29c6ebec
SHA-256: b3ed7bed9538b88e5379321c8191ded787985d6621f01fcdc1714152692af80c
Size: 45.97 kB - librabbitmq-devel-0.9.0-6.el8_10.i686.rpm
MD5: 2745f47914fa9be68b072b392c89006a
SHA-256: 157665372eebcb7336ade1b3cf6a431576dda93b6b738898998d37a3caae73c7
Size: 52.88 kB - librabbitmq-devel-0.9.0-6.el8_10.x86_64.rpm
MD5: 858bca5a2040e4dc2f0b230655f61ccf
SHA-256: c5921c42580b05b13ef847146d2240f34f779af26ad879fc358f2cc74bf9966c
Size: 52.86 kB - librabbitmq-tools-0.9.0-6.el8_10.x86_64.rpm
MD5: 84cfea72a94e1e02d3b0a92a9692b040
SHA-256: d535f4a06f6b827f3ec61a436d878c442507fa0fdea5ad669bcf0b3d357d79c7
Size: 46.36 kB